Guide · 04 of 05

SPRS Scoring Deep-Dive

How the -203 to 110 scoring works, what each control is worth, and how the 88-point conditional Level 2 threshold actually behaves.

Reading time: ~8 minLast updated: June 2026Topic: Scoring & assessment

What SPRS actually is

The Supplier Performance Risk System (SPRS) is the DoD's contractor-facing reporting platform for cybersecurity posture. Contractors holding contracts with DFARS 252.204-7012 are required to maintain a current self-assessed (or assessor-validated) score in SPRS. The score is computed against NIST SP 800-171 Rev. 2 using the DoD Assessment Methodology v1.2.1, published by DoD CIO.

A current SPRS score is one of the most-checked items in prime contractor due diligence. Primes routinely require subcontractors to maintain SPRS scores above defined thresholds (often 88, sometimes higher) as a condition of working on certain contracts.

The scoring math

You start at 110 points. Each control you do not fully implement deducts a point value: 1, 3, or 5 points, depending on the control's weight under the DoD Assessment Methodology. The methodology assigns point values based on the perceived security impact of the control — controls that block major attack vectors weigh more, controls that address narrower issues weigh less.

The scoring sums these deductions. If you have not implemented controls worth 22 points total, your score is 88. If you have not implemented controls worth 50 points total, your score is 60. The math is additive and direct.

Why scores can go negative

The total available deductions exceed the starting 110 points. Specifically, the 110 controls collectively carry 313 points of available deductions. So a contractor with zero implementation of NIST 800-171 starts at 110 and can lose up to 313 points, ending at -203. This is the bottom of the scoring scale.

Most contractors at the start of their CMMC journey score somewhere between -50 and +60. A score in the 70-85 range usually indicates a contractor with substantial work already done but specific gaps remaining. Above 88 is the conditional Level 2 threshold.

The 88-point conditional Level 2 threshold

Under the CMMC program, contractors who score at or above 88 are eligible for Conditional Level 2 status. This means the C3PAO can issue conditional certification with the contractor's outstanding gaps documented in a POA&M, provided those gaps are closed within 180 days.

Below 88, conditional certification is not available. The contractor must remediate to at least 88 before the assessor will issue any certification. In practice, most assessors recommend remediating to 95+ before scheduling the formal assessment, because the conditional status is brittle — if even one POA&M item slips past 180 days, the conditional status is revoked.

The 180-day rule, more precisely

180 days from the date of the conditional certification, every item on the POA&M must be closed. "Closed" means implemented, evidenced, and confirmable. If any item remains open, the conditional status converts to non-certified, and the contractor must re-engage the C3PAO for re-assessment.

The practical strategy: implement everything that's high-point-value or risky before assessment. Defer only the genuinely-deferrable items into the POA&M. Make the POA&M short and time-bounded. Schedule the assessment when SPRS is comfortably above 88 — 95+ is the typical safe target.

Self-assessment vs. assessor-validated

SPRS scores can be posted in two ways:

  • Self-assessed: The contractor evaluates against NIST 800-171, computes the score, and posts. Valid for contracts that allow self-assessed Level 2 (declining in scope as Phase 2 enforcement takes hold).
  • Assessor-validated: A C3PAO performs the formal CMMC Level 2 assessment, validates the score, and the score is posted with assessor attestation. This is what's required post-Phase 2 for most CUI-bearing contracts.

Self-assessed scores carry less weight in due diligence and are commonly contested by primes asking for evidence. Assessor-validated scores carry the C3PAO's professional reputation behind them.

Where contractors most commonly over-score themselves

External validation work consistently reveals that contractors self-score 15-25 points higher than their assessor-grade score. The reason is interpretation. Contractors apply the controls generously; assessors apply them strictly to the assessment objectives in NIST SP 800-171A.

Specific patterns where self-scoring breaks down:

  • Multi-factor authentication (AC.L2-3.5.3) — counted as "yes, we have MFA" when the actual control requires MFA for privileged accounts AND remote access AND specific other conditions. Partial implementation is partial credit, not full.
  • Audit logging (AU family) — counted as "yes, we log" when the actual control requires defined audit event types, defined retention, and evidence of regular review.
  • Configuration baselines (CM.L2-3.4.1, 3.4.2) — counted as "yes, we have a baseline" when the actual control requires documented configuration baselines that are enforced and verified.
  • Vulnerability remediation (RA.L2-3.11.2, 3.11.3) — counted as "yes, we scan" when the actual control requires that scan findings are remediated within documented SLAs and evidence shows the remediation actually happening.

The fix is not "score yourself lower." The fix is to assess against the 320 assessment objectives in NIST 800-171A with assessor-grade discipline. If you can't show evidence that the practice operates as the objective describes, you score it as not-met.

Maintaining the score

SPRS scores are time-stamped. DoD requires posting a current score, and contractors are expected to update the score when material changes occur in their environment. Most contractors update on an annual cadence, aligning with their NIST 800-171 self-assessment cycle.

The retainer model exists in part to keep SPRS scores current as environments change — new tools added, M&A activity, contract changes, new CUI categories handled. Static SPRS scores in a changing environment decay quickly, and stale scores trigger prime contractor scrutiny.

— Ready to put this to work

Start the intake. See a live estimate as you fill it in.

Start your assessment